The approval prompt is lying: a critical coding agent security flaw (opens in new tab)
submitted by SymJack is a new attack technique targeting AI coding agents: a booby-trapped repository to trick your AI coding assistant into overwriting its own configuration through a disguised file copy, then run attacker code on the next restart. This is one technique that works against the whole category, don’t treat it as six separate bugs.
Read the original article